Published on July 29, 2026

CISA Shares Guidance on Isolating Vital Systems During Cyberattacks


Severity

Medium

Detail          

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with international cybersecurity partners, has released new guidance advising critical infrastructure organizations to prepare for cyberattacks by implementing isolation strategies that allow essential systems to continue operating even when enterprise IT environments are compromised. The guidance is part of the CI Fortify initiative, which focuses on improving operational resilience through proactive isolation and rapid recovery planning.

Rather than relying solely on traditional incident response measures, the guidance encourages organizations to design their environments so that critical Operational Technology (OT) and supporting systems can be isolated from corporate networks, third-party connections, and internet-facing services during a major cyber incident. This approach aims to reduce the impact of ransomware, nation-state attacks, and destructive malware while maintaining delivery of essential services.

Below are the 5 Key Recommendations for Isolating Vital Systems During Cyberattacks.

  1. Identify and Prioritize Vital Systems
    • Organizations should first determine which systems are essential for maintaining critical operations and business continuity. This includes:
      • Identify operational technology (OT) systems and critical business applications that must remain functional during an attack.
      • Map system dependencies, including third-party services and communication links.
      • Determine which supporting infrastructure is required for essential operations.
      • Document critical assets and establish recovery priorities.
      • Regularly review and update the inventory as environments evolve.
    • The objective is to clearly define which systems require the highest level of protection and isolation.
  2. Prepare Isolation Capabilities Before an Incident
    • solation should be planned and tested in advance rather than performed reactively during an attack. Organizations should:
      • Design network segmentation between IT and OT environments.
      • Implement the ability to disconnect non-essential external connections quickly.
      • Use dedicated or encrypted communication paths for critical systems.
      • Reduce unnecessary dependencies on corporate IT infrastructure.
      • Establish documented procedures for initiating isolation during emergencies.
    • Having predefined isolation mechanisms enables faster response while minimizing operational disruption.
  3. Maintain Essential Operations While Isolated
    • The goal of isolation is not to shut down operations, but to continue delivering essential services safely. Organizations should:
      • Ensure vital systems can function independently from compromised enterprise networks.
      • Prepare manual operating procedures where automation becomes unavailable.
      • Verify that critical services remain operational without internet connectivity where possible.
      • Test business continuity procedures under isolated operating conditions.
      • Ensure personnel are trained to operate during degraded network conditions.
    • Organizations should assume that telecommunications providers, cloud services, and external dependencies may become unavailable during a major cyber event.
  4. Continuously Monitor the Isolated Environment
    • After isolation is activated, organizations must verify that the separation remains effective. Recommended practices include:
      • Monitor routing tables and network traffic for unexpected connectivity.
      • Validate that unauthorized paths have not reconnected isolated systems.
      • Continuously monitor intrusion detection and security monitoring systems.
      • Secure network management zones used to administer routers, switches, and firewalls.
      • Review system integrity throughout the isolation period.
    • Continuous monitoring helps ensure attackers cannot regain access through overlooked network paths.
  5. Plan for Safe Recovery and Restoration
    • Recovery planning should begin before an incident occurs and be regularly exercised. Organizations should:
      • Maintain secure backups of critical systems and configurations.
      • Develop procedures for rebuilding compromised systems rapidly.
      • Test recovery plans through tabletop and operational exercises.
      • Verify system integrity before reconnecting isolated environments.
      • Restore external connectivity only after confirming threats have been eliminated.
    • Recovery planning reduces downtime and helps organizations safely return to normal operations following containment.

Conclusion

CISA’s latest guidance emphasizes that cyber resilience extends beyond detecting and responding to attacks. Organizations should proactively design their infrastructure so that vital systems can be isolated from compromised environments while continuing to deliver essential services. By identifying critical assets, implementing effective network isolation, maintaining operational continuity, continuously monitoring isolated environments, and preparing comprehensive recovery plans, organizations can significantly reduce the impact of ransomware and other large-scale cyberattacks while strengthening overall operational resilience.

Source

https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks